AZ-700 exam dumps

AZ-700 practice question 252 of 310

Designing and Implementing Microsoft Azure Networking Solutions. Professional level, Microsoft. Free question with the correct answer and a full explanation.

AZ-700 Question 252

Select 2

You have an Azure Storage account and a Virtual Network (VNet) in the same region. You want to limit storage access to a single subnet named SubnetA using service endpoints. You have already enabled the Storage service endpoint on SubnetA, but connections from the public internet are still possible. Which steps should you take to ensure traffic is restricted to SubnetA only? (Choose two.)

  1. A

    Enable �Allow access from all networks� in the storage account� firewall settings.

  2. B

    Switch the storage account firewall to �Selected networks� and add SubnetA as an allowed subnet.

  3. C

    Configure Azure Private Link for the storage account to disable the public endpoint completely.

  4. D

    Remove or disable any public IP addresses explicitly allowed in the storage account firewall settings.

  5. E

    Enable the Storage service endpoint on every subnet in the VNet, regardless of usage.

Show answer and explanation

Correct answers: B, D

Explanation

To properly restrict access to an Azure Storage account using service endpoints, you must enable the service endpoint on the desired subnet (SubnetA) and then configure the storage account firewall to �Selected networks.� Add SubnetA to the list of allowed networks and remove any public IP addresses from the allow list if you want to prevent external access. Refer to Microsoft� documentation on using service endpoints (https://learn.microsoft.com/azure/virtual-network/virtual-network-service-endpoints-overview) to ensure you follow the correct regional and configuration requirements.

  • A. Incorrect.

    Option 1 is incorrect because choosing �Allow access from all networks� will continue to allow connections from the public internet, which defeats the purpose of restricting access to the subnet.

  • B. Correct.

    Option 2 is correct. Setting the storage account firewall to �Selected networks� ensures that only specified subnets (in this case, SubnetA) can access the storage. After adding SubnetA, traffic from other networks is blocked.

  • C. Incorrect.

    Option 3 is incorrect for this scenario because while Azure Private Link can limit access, it introduces a private endpoint rather than using service endpoints directly. It is a separate approach for controlling access and not strictly required here.

  • D. Correct.

    Option 4 is correct. If there are any public IP addresses listed in the storage account firewall, they would still allow external access. You must remove them (unless specifically required) to restrict traffic exclusively to your subnet.

  • E. Incorrect.

    Option 5 is incorrect because enabling the Storage service endpoint on subnets not involved in accessing the storage account is unnecessary. Service endpoints need only be enabled for the subnets that actually require access to the service.

Timed practice exam

Take a AZ-700 practice test under exam conditions

70 questions in 100 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam